855dcd36...2ca3 | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 98/100
Dynamic Analysis Report
Classification: -
Threat Names: -

VMRay Threat Identifiers (13 rules, 19 matches)

SeverityCategoryOperationCountClassification
4/5
User Data ModificationModifies Windows automatic backups1-
4/5
InjectionWrites into the memory of another running process1-
4/5
InjectionModifies control flow of another process1-
3/5
Anti AnalysisTries to evade debugger1-
3/5
YARASuspicious content matched by YARA rules2-
2/5
ObfuscationResolves APIs dynamically to possibly evade static detection1-
2/5
Anti AnalysisCreates an unusually large number of processes1-
2/5
Anti AnalysisMakes direct system call to possibly evade hooking based sandboxes2-
1/5
Hide TracksCreates process with hidden window5-
1/5
ObfuscationCreates a page with write and execute permissions1-

Screenshots

Monitored Processes

Process GraphProcess Graph Legend

MITRE ATT&CK™ Matrix - Windows

ActiveAll
Version: 2019-04-25 20:53:07.719000
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Software Packing
Hidden Window
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Standard Application Layer Protocol
Exfiltration
Impact
Inhibit System Recovery

Sample Information

ID#834767
MD5
a4e1caab1b9642ef645b6549ca09d303
SHA1
da0cd782f32088c0df8cd62deda1c61b4cedd6fb
SHA256
855dcd368dbb01539e7efa4b3fefa9b56d197db87b1ba3ede5e1f95927ea2ca3
SSDeep
768:nAqGAtr4sozjTFpy3RlyvK6WZmYNnYIzxz84k567+tb+pA:AqGcAFp6ynCvNnY8t8Z5E+t6p
ImpHash
3c9f900665a4beb93988dde083f7e392
FilenameBUDDINGPULVERS.exe
File Size88.00 KB
Sample TypeWindows Exe (x86-32)

Analysis Information

Creation Time2020-05-09 23:05 (UTC+)
Analysis Duration00:04:00
Number of Monitored Processes89
Execution SuccessfulTrue
Reputation EnabledTrue
WHOIS EnabledFalse
Local AV EnabledTrue
Local AV Applied OnSample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps
YARA EnabledTrue
YARA Applied OnSample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps
Number of AV Matches0
Number of YARA Matches10
Termination ReasonTimeout
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image